High - CVE-2024-12838 - The passwordless login mechanism in CGFIDO from...
The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted...
High - CVE-2024-12839 - The login mechanism via device authentication...
The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program...
High - CVE-2024-13040 - The QOCA aim from Quanta Computer has an...
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access...
High - CVE-2024-45497 - A flaw was found in the OpenShift build...
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the...
NA - CVE-2024-11972 - The Hunk Companion WordPress plugin before...
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress...
NA - CVE-2024-13067 - A vulnerability was found in CodeAstro Online...
A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All...
NA - CVE-2024-49422 - Protection Mechanism Failure in bootloader...
Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for...
NA - CVE-2024-56212 - Improper Neutralization of Special Elements...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DeluxeThemes Userpro.This issue affects Userpro: from n/a through 5.1.9.